[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2001-0736Date: (C)2001-10-18   (M)2023-12-22


Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://marc.info/?l=bugtraq&m=98749102621604&w=2
http://marc.info/?l=bugtraq&m=99106787825229&w=2
MDKSA-2001:047
RHSA-2001:042
pine-tmp-file-symlink(6367)

CPE    8
cpe:/o:engardelinux:secure_linux:1.0.1
cpe:/o:mandrakesoft:mandrake_linux:7.2
cpe:/o:mandrakesoft:mandrake_linux:7.1
cpe:/o:mandrakesoft:mandrake_linux:8.0
...

© SecPod Technologies